View a markdown version of this page

Actions, resources, and condition keys for AWS Certificate Manager - Service Authorization Reference

Actions, resources, and condition keys for AWS Certificate Manager

AWS Certificate Manager (service prefix: acm) provides the following service-specific operations, resources, actions, and condition keys for use in IAM permission policies.

References:

API operations defined by AWS Certificate Manager

The following table maps API operations to the IAM actions they authorize. Only condition keys that have static values for the given API and action are listed; for the full set of condition keys supported by each action, see the Actions table.

Operation IAM action Condition key Possible value(s) Access level

AddTagsToCertificate

acm:AddTagsToCertificate

Tagging, Write

DeleteCertificate

acm:DeleteCertificate

Write

DescribeCertificate

acm:DescribeCertificate

Read

ExportCertificate

acm:ExportCertificate

Read

GetAccountConfiguration

acm:GetAccountConfiguration

Read

GetCertificate

acm:GetCertificate

Read

ImportCertificate

acm:AddTagsToCertificate

Tagging, Write

acm:ImportCertificate

Write

ListCertificateDomainValidations

acm:ListCertificateDomainValidations

List

ListCertificates

acm:ListCertificates

List

ListTagsForCertificate

acm:ListTagsForCertificate

Read

ListTagsForResource

acm:ListTagsForResource

Read

PutAccountConfiguration

acm:PutAccountConfiguration

Write

RemoveTagsFromCertificate

acm:RemoveTagsFromCertificate

Tagging, Write

RenewCertificate

acm:RenewCertificate

Write

RequestCertificate

acm:AddTagsToCertificate

Tagging, Write

acm:RequestCertificate

Write

ResendValidationEmail

acm:ResendValidationEmail

Write

RevokeCertificate

acm:RevokeCertificate

Write

SearchCertificates

acm:SearchCertificates

List

TagResource

acm:TagResource

Tagging, Write

UntagResource

acm:UntagResource

Tagging, Write

UpdateCertificateOptions

acm:UpdateCertificateOptions

Write

Actions defined by AWS Certificate Manager

You can specify the following actions in the Action element of an IAM policy statement. Use policies to grant permissions to perform an operation in AWS. When you use an action in a policy, you usually allow or deny access to the API operation or CLI command with the same name. However, in some cases, a single action controls access to more than one operation. Alternatively, some operations require several different actions.

Actions Description Resource types (*required) Condition keys Access level

AddTagsToCertificate

Grants permission to add one or more tags to a certificate

certificate*

acm:CertificateKeyPairOrigin

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

Tagging, Write

CreateAcmeDomainValidation

Grants permission to create an ACME domain validation

acme-endpoint*

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

Write

CreateAcmeEndpoint

Grants permission to create an ACME endpoint

aws:RequestTag/${TagKey}

aws:TagKeys

Write

CreateAcmeExternalAccountBinding

Grants permission to create an ACME external account binding

acme-endpoint*

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

Write

DeleteAcmeDomainValidation

Grants permission to delete an ACME domain validation

acme-domain-validation*

aws:ResourceTag/${TagKey}

Write

DeleteAcmeEndpoint

Grants permission to delete an ACME endpoint

acme-endpoint*

aws:ResourceTag/${TagKey}

Write

DeleteAcmeExternalAccountBinding